IOC Report
https://pub-9445ce0d74714d1c934c51ffcf83c3f2.r2.dev/slnt.html?nycsbs

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 198
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 199
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 200
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 201
ASCII text, with very long lines (314), with CRLF line terminators
downloaded
Chrome Cache Entry: 202
ASCII text, with very long lines (27809)
downloaded
Chrome Cache Entry: 203
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 204
ASCII text, with very long lines (301), with CRLF line terminators
downloaded
Chrome Cache Entry: 205
ASCII text, with very long lines (27809)
downloaded
Chrome Cache Entry: 206
Unicode text, UTF-8 (with BOM) text, with very long lines (434), with CRLF line terminators
downloaded
Chrome Cache Entry: 207
ASCII text, with very long lines (356), with CRLF line terminators
downloaded
Chrome Cache Entry: 208
HTML document, ASCII text, with very long lines (65390)
downloaded
Chrome Cache Entry: 209
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 210
Unicode text, UTF-8 (with BOM) text, with very long lines (529), with CRLF line terminators
dropped
Chrome Cache Entry: 211
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 212
Web Open Font Format (Version 2), TrueType, length 22904, version 0.0
downloaded
Chrome Cache Entry: 213
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 214
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 215
HTML document, ASCII text, with very long lines (322), with CRLF line terminators
dropped
Chrome Cache Entry: 216
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 217
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 218
exported SGML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 219
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 220
Unicode text, UTF-8 text, with very long lines (37565)
dropped
Chrome Cache Entry: 221
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 222
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 223
ASCII text, with very long lines (32047)
downloaded
Chrome Cache Entry: 224
ASCII text, with very long lines (1245), with no line terminators
downloaded
Chrome Cache Entry: 225
ASCII text, with very long lines (316), with CRLF line terminators
downloaded
Chrome Cache Entry: 226
Unicode text, UTF-8 (with BOM) text, with very long lines (497), with CRLF line terminators
downloaded
Chrome Cache Entry: 227
Unicode text, UTF-8 (with BOM) text, with very long lines (7625), with CRLF line terminators
downloaded
Chrome Cache Entry: 228
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 229
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 230
Unicode text, UTF-8 text, with very long lines (37565)
downloaded
Chrome Cache Entry: 231
ASCII text, with very long lines (878), with CRLF line terminators
downloaded
Chrome Cache Entry: 232
ASCII text, with very long lines (31463), with no line terminators
downloaded
Chrome Cache Entry: 233
Web Open Font Format, TrueType, length 41280, version 0.0
downloaded
Chrome Cache Entry: 234
Unicode text, UTF-8 text, with very long lines (65514), with no line terminators
downloaded
Chrome Cache Entry: 235
JSON data
dropped
Chrome Cache Entry: 236
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 237
Unicode text, UTF-8 (with BOM) text, with very long lines (1072), with CRLF line terminators
downloaded
Chrome Cache Entry: 238
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 239
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 240
JSON data
dropped
Chrome Cache Entry: 241
Unicode text, UTF-8 (with BOM) text, with very long lines (34199), with CRLF line terminators, with escape sequences
downloaded
Chrome Cache Entry: 242
ASCII text, with very long lines (421), with CRLF line terminators
downloaded
Chrome Cache Entry: 243
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 244
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 245
JSON data
dropped
Chrome Cache Entry: 246
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 247
ASCII text, with very long lines (395), with CRLF line terminators
downloaded
Chrome Cache Entry: 248
Unicode text, UTF-8 (with BOM) text, with very long lines (653), with CRLF line terminators
downloaded
Chrome Cache Entry: 249
ASCII text, with very long lines (327), with CRLF line terminators
downloaded
Chrome Cache Entry: 250
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 251
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 252
GIF image data, version 89a, 1181 x 1181
dropped
Chrome Cache Entry: 253
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 254
JSON data
downloaded
Chrome Cache Entry: 255
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
dropped
Chrome Cache Entry: 256
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 257
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
downloaded
Chrome Cache Entry: 258
Unicode text, UTF-8 text, with very long lines (65520), with no line terminators
downloaded
Chrome Cache Entry: 259
Unicode text, UTF-8 (with BOM) text, with very long lines (36076), with CRLF line terminators
downloaded
Chrome Cache Entry: 260
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 261
Unicode text, UTF-8 text, with very long lines (64241)
downloaded
Chrome Cache Entry: 262
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 263
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 264
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 265
Unicode text, UTF-8 text, with very long lines (64174)
downloaded
Chrome Cache Entry: 266
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 267
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 268
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 269
ASCII text, with very long lines (385), with CRLF line terminators
downloaded
Chrome Cache Entry: 270
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 271
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 272
Unicode text, UTF-8 (with BOM) text, with very long lines (480), with CRLF line terminators
downloaded
Chrome Cache Entry: 273
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 274
Unicode text, UTF-8 (with BOM) text, with very long lines (512), with CRLF line terminators
downloaded
Chrome Cache Entry: 275
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 276
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 277
Web Open Font Format, TrueType, length 33556, version 0.0
downloaded
Chrome Cache Entry: 278
Web Open Font Format, TrueType, length 35900, version 0.0
downloaded
Chrome Cache Entry: 279
ASCII text, with very long lines (4050), with no line terminators
downloaded
Chrome Cache Entry: 280
Unicode text, UTF-8 (with BOM) text, with very long lines (512), with CRLF line terminators
dropped
Chrome Cache Entry: 281
Unicode text, UTF-8 (with BOM) text, with very long lines (529), with CRLF line terminators
downloaded
Chrome Cache Entry: 282
ASCII text, with very long lines (42133)
downloaded
Chrome Cache Entry: 283
Unicode text, UTF-8 (with BOM) text, with very long lines (503), with CRLF line terminators
downloaded
Chrome Cache Entry: 284
ASCII text, with very long lines (318), with CRLF line terminators
downloaded
Chrome Cache Entry: 285
JSON data
downloaded
Chrome Cache Entry: 286
ASCII text, with very long lines (816), with CRLF line terminators
downloaded
Chrome Cache Entry: 287
Web Open Font Format, TrueType, length 2576, version 1.0
downloaded
Chrome Cache Entry: 288
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 289
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
dropped
Chrome Cache Entry: 290
Unicode text, UTF-8 (with BOM) text, with very long lines (16609), with CRLF line terminators
downloaded
Chrome Cache Entry: 291
GIF image data, version 89a, 1181 x 1181
downloaded
Chrome Cache Entry: 292
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 293
JSON data
dropped
Chrome Cache Entry: 294
JSON data
dropped
Chrome Cache Entry: 295
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 296
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 297
Unicode text, UTF-8 (with BOM) text, with very long lines (480), with CRLF line terminators
dropped
Chrome Cache Entry: 298
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 299
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 300
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 301
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 302
Unicode text, UTF-8 (with BOM) text, with very long lines (434), with CRLF line terminators
dropped
Chrome Cache Entry: 303
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 304
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 305
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 306
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 307
exported SGML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 308
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 309
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 310
Unicode text, UTF-8 text, with very long lines (557), with CRLF line terminators
downloaded
Chrome Cache Entry: 311
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 312
Unicode text, UTF-8 (with BOM) text, with very long lines (503), with CRLF line terminators
dropped
Chrome Cache Entry: 313
ASCII text, with very long lines (32089)
downloaded
Chrome Cache Entry: 314
ASCII text, with very long lines (65397)
downloaded
Chrome Cache Entry: 315
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 316
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 317
ASCII text, with very long lines (312), with CRLF line terminators
downloaded
Chrome Cache Entry: 318
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 319
JSON data
downloaded
Chrome Cache Entry: 320
ASCII text, with very long lines (415), with CRLF line terminators
downloaded
Chrome Cache Entry: 321
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
downloaded
Chrome Cache Entry: 322
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 323
ASCII text, with very long lines (42133)
downloaded
Chrome Cache Entry: 324
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 325
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 326
Unicode text, UTF-8 (with BOM) text, with very long lines (497), with CRLF line terminators
dropped
Chrome Cache Entry: 327
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 328
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 329
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 330
HTML document, ASCII text, with very long lines (322), with CRLF line terminators
downloaded
Chrome Cache Entry: 331
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 332
JSON data
downloaded
Chrome Cache Entry: 333
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 334
Unicode text, UTF-8 text, with very long lines (64241)
downloaded
Chrome Cache Entry: 335
PNG image data, 2560 x 546, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 336
ASCII text, with very long lines (402)
downloaded
Chrome Cache Entry: 337
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 338
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 339
ASCII text, with very long lines (65450), with CRLF line terminators
downloaded
Chrome Cache Entry: 340
ASCII text, with very long lines (378), with CRLF line terminators
downloaded
There are 134 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2148 --field-trial-handle=2076,i,6033540543535417587,3270224675351158564,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://pub-9445ce0d74714d1c934c51ffcf83c3f2.r2.dev/slnt.html?nycsbs"

URLs

Name
IP
Malicious
https://pub-9445ce0d74714d1c934c51ffcf83c3f2.r2.dev/slnt.html?nycsbs
malicious
https://pub-9445ce0d74714d1c934c51ffcf83c3f2.r2.dev/slnt.html?nycsbs
malicious
https://aka.ms/youngpeopleprivacy
unknown
http://www.apache.org/licenses/LICENSE-2.0
unknown
https://icon-library.com/images/loading-icon-animated-gif/loading-icon-animated-gif-7.jpg
104.26.10.155
http://live.xbox.com/MyXbox/Profile
unknown
https://upload.wikimedia.org/wikipedia/commons/thumb/9/96/Microsoft_logo_%282012%29.svg/2560px-Micro
unknown
https://mattcooperfamilylaw.sharepoint.com/:b:/g/EQHRsiZsHXdDisO3M3swRP0BfVMXsv1uIFWH41KS1v0d_g?e=4%
unknown
http://knockoutjs.com/
unknown
https://github.com/chemerisuk/better-dom
unknown
about:blank
http://www.json.org/json2.js
unknown
https://aka.ms/dpa
unknown
https://upload.wikimedia.org/wikipedia/commons/thumb/9/96/Microsoft_logo_%282012%29.svg/2560px-Microsoft_logo_%282012%29.svg.png
185.15.59.240
http://NSwag.org)
unknown
https://www.w3.org/TR/wai-aria-practices/examples/dialog-modal/css/datepicker.css
104.18.22.19
https://onedrive.live.com/
unknown
http://www.opensource.org/licenses/mit-license.php)
unknown
https://minecraft.net
unknown
https://aka.ms/privacy
2.18.238.120
https://outlook.live.com/mail/inbox
unknown
https://www.w3.org/WAI/ARIA/apg/
104.18.22.19
http://goo.gl/MqrFmX
unknown
https://api.telegram.org/bot$
unknown
https://logo.clearbit.com/
13.32.27.77
https://github.com/h5bp/html5-boilerplate/blob/master/src/css/main.css
unknown
https://js.monitor.azure.com/scripts/c/ms.analytics-web-3.gbl.min.js
13.107.246.60
http://github.com/requirejs/almond/LICENSE
unknown
https://github.com/chemerisuk/better-dateinput-polyfill
unknown
https://i.imgur.com/aqOTSn0.png
199.232.192.193
There are 19 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
waws-prod-am2-46f973ed.sip.p.azurewebsites.windows.net
20.76.252.24
d26p066pn2w0s0.cloudfront.net
13.32.27.77
edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
217.20.57.34
pub-9445ce0d74714d1c934c51ffcf83c3f2.r2.dev
104.18.3.35
www.google.com
142.250.186.100
upload.wikimedia.org
185.15.59.240
www.w3.org
104.18.22.19
aka.ms
2.18.238.120
icon-library.com
104.26.10.155
s-part-0032.t-0009.t-msedge.net
13.107.246.60
ipv4.imgur.map.fastly.net
199.232.192.193
windowsupdatebg.s.llnwi.net
87.248.204.0
js.monitor.azure.com
unknown
assets.onestore.ms
unknown
i.s-microsoft.com
unknown
ajax.aspnetcdn.com
unknown
c.s-microsoft.com
unknown
i.imgur.com
unknown
logo.clearbit.com
unknown
There are 9 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.18.3.35
pub-9445ce0d74714d1c934c51ffcf83c3f2.r2.dev
United States
13.32.27.77
d26p066pn2w0s0.cloudfront.net
United States
13.107.246.60
s-part-0032.t-0009.t-msedge.net
United States
192.168.2.6
unknown
unknown
104.18.22.19
www.w3.org
United States
192.168.2.5
unknown
unknown
185.15.59.240
upload.wikimedia.org
Netherlands
199.232.192.193
ipv4.imgur.map.fastly.net
United States
172.67.68.224
unknown
United States
20.76.252.24
waws-prod-am2-46f973ed.sip.p.azurewebsites.windows.net
United States
104.26.10.155
icon-library.com
United States
239.255.255.250
unknown
Reserved
142.250.185.196
unknown
United States
142.250.186.100
www.google.com
United States
2.18.238.120
aka.ms
European Union
There are 5 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://pub-9445ce0d74714d1c934c51ffcf83c3f2.r2.dev/slnt.html?nycsbs
malicious
https://privacy.microsoft.com/en-us/privacystatement
https://privacy.microsoft.com/en-US/updates
https://privacy.microsoft.com/en-us/privacystatement#maincookiessimilartechnologiesmodule
https://privacy.microsoft.com/en-us/privacystatement#maincookiessimilartechnologiesmodule
https://privacy.microsoft.com/en-us/privacystatement#mainwherewestoreandprocessdatamodule
https://www.microsoft.com/en-us/concern/privacy
https://www.microsoft.com/en-us/concern/privacy
https://www.microsoft.com/en-us/concern/privacy
https://www.microsoft.com/en-us/concern/privacy
about:blank
https://www.microsoft.com/store/buy/cartcount
https://privacy.microsoft.com/en-US/privacystatement#mainhowtocontactusmodule
https://privacy.microsoft.com/en-US/privacystatement#mainhowtocontactusmodule
https://privacy.microsoft.com/en-us/privacystatement#mainenterprisedeveloperproductsmodule
https://privacy.microsoft.com/en-us/privacystatement#mainnoticetoendusersmodule
https://privacy.microsoft.com/en-us/privacystatement#mainnoticetoendusersmodule
https://privacy.microsoft.com/en-us/privacystatement#mainmicrosoftaccountmodule
There are 8 hidden doms, click here to show them.